Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-70280
HistoryJul 30, 2023 - 12:00 a.m.

Apache InLong Deserialization Vulnerability (CNVD-2023-70280)

2023-07-3000:00:00
China National Vulnerability Database
www.cnvd.org.cn
6
apache
inlong
deserialization
vulnerability
data integration
framework
security
file access
attack
cnvd-2023-70280

EPSS

0.004

Percentile

73.7%

Apache InLong is the U.S. Apache (Apache) Foundation’s one-stop massive data integration framework. Provides automated, secure and reliable data transfer capabilities. A deserialization vulnerability exists in Apache InLong versions 1.4.0 to 1.7.0. The vulnerability stems from insecure deserialization processing by an application receiving serialized data submitted by a user, which can be exploited by an attacker to bypass the current logic and read arbitrary files.

EPSS

0.004

Percentile

73.7%